Open source · Cloud & Platform

Kubernetes Manifest Policy Linter

Lint Kubernetes manifests for policy, ownership, resource and rollout gaps.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

TOOLID=k8s-manifest-policy-linter. A zero-dependency Node 22+ offline policy check for a local JSON export of Kubernetes manifests. JSON is a Kubernetes-compatible YAML subset, but this tool does not parse arbitrary YAML. It consults its pinned data/schemas.json subset and never contacts a cluster, loads kubeconfig, pulls an image, or changes a deployment.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/k8s-manifest-policy-linter.mjs --root examples/passing --policy policy.json --manifests manifests.json
node bin/k8s-manifest-policy-linter.mjs --root examples/failing --policy policy.json --manifests manifests.json

Read the result

The first example exits 0. The second exits 1 with separate unsupported-api-version and resource-limit-missing findings. @manifests, @policy, and @schemas are logical source roles, not host paths. A pointer such as /manifests/1/manifest/spec/template/spec/containers/0/resources/limits locates evidence within the exact exported bundle named at invocation. No object name, image reference, owner value or file path is echoed.

Where this check stops

Bundle 1,048,576 bytes; policy 65,536 bytes; JSON depth 16; 1,000 manifests; 5,000 containers; evaluation time 5,000 ms with injected clock. Bounds are inclusive; N+1 is incomplete for bundle evidence or invalid configuration for policy. Inputs are strictly decoded UTF-8 and realpath-confined within --root. The tool writes nothing and makes no network calls. No arbitrary YAML reader, full API-server schema, admission controller, live cluster state, kubeconfig, deployment action or auto-fix is included. The library exports TOOLID, LIMITS, RULES, validPolicy, validSchemas, and lintManifests(bundle,policy,schemas,{now,deadline}).

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.